CVE-2026-8054 — dotCMS Core Publish Audit API SQL Injection
aretiq.ai | research | CVE-2026-8054 | #vulnerability-research | #sql-injection | #pre-auth | #cve-2026-8054 | #dotcms | #content-management-system
Summary
CVE-2026-8054: unauthenticated SQL injection in dotCMS's /api/auditPublishing/getAll endpoint gives full read, modify and delete access to the PostgreSQL database in one request.
- CVE
- CVE-2026-8054
- Published
- Collected
Skip to content